Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

opencode-1-docker, opencode-1.18-docker, opencode-1.18.34-docker, opencode-docker

Index digest:

sha256:e54bcea4015f893737606f31867f016a888f6161af71b557c929aed5410f2680

Manifest digest:

sha256:1fc8c43a8eb40a9b1f986ac63c78543676813831bb5d31306e0c785a507577a0

Size

585.18 MB

Last pushed

12 hours ago

Vulnerabilities

0
9
10
42
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:5365a92f912955c674dc505952d22b12e17bbf73e62f946e86f9c78346080d68
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:07a185144071b1ee042d760fe1af57e4de16d3bff54ffb72bf8dc19ddb7603e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:88bb3c3b5235f6b69361f60f19a73f21c6b535c263f154f1fb16c7c20402a1ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:60e26c4d8f239e70c6a2353c95846ad326afd60f1597923350834c3810bac163
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:7900b0e5c09328bad26dbac01777f2914825889e16f33cb1860d8c3f6cf784de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:c76f21c9bf180c81399f70ef29fbeb78396bf1a36f598ccb2c995c1e6e765d8a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:efabd072c22a4a9068c9fddd5a2c210e5e6d9d86df2b580c7eb67abb04236d62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:5e90b01ba8bbcce2f33b63e78018b6ed5f56cac1eadd4540f79036ee65230d47
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:9922c288b10683bc63f9eeba2648fa404af9ac95d705b5ae9a1771790e72489c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:95802cbbe497c967d74eb684e14852bd754cf66a44895a86afab3c1631efac15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:5a35d72e0ceec3d10866ae258d4337f0467eec0a36a6b53316af51a90986f2d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:f74bc3be15a2a7b3df4b3c8b04f3a7abdc4cce1c574a5cf284561029977212ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:43271e26dceb708002beaf820b1065f2803f39be48f77871f74a55e8668e4042
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:e940fce0f5bb90fdb712660fedb5e716379da5f26d6317bac99e7e988a16ad82
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:bc39ffa12aad09a8ee64bf0ed5bb955bb33fa5fb25026f711390689ded8f314d